Browse all 9 CVE security advisories affecting hogash. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Hogash develops web applications and themes primarily for e-commerce and content management platforms. Historically, their products have been susceptible to multiple remote code execution (RCE) vulnerabilities, cross-site scripting (XSS), and privilege escalation flaws, with nine CVEs documented to date. These issues often stem from insufficient input validation and improper access controls. While no major public security incidents have been widely reported, the consistent pattern of vulnerabilities in their software suggests a need for improved security practices in their development lifecycle.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-63061 | WordPress KALLYAS theme < 4.25.0 - Cross Site Scripting (XSS) vulnerability — KALLYAS CWE-79 | 6.5 | Medium | 2025-12-09 |
| CVE-2025-63060 | WordPress KALLYAS theme < 4.25.0 - Cross Site Request Forgery (CSRF) vulnerability — KALLYAS CWE-352 | 4.3 | Medium | 2025-12-09 |
| CVE-2025-62018 | WordPress Kallyas theme <= 4.22.0 - Broken Access Control vulnerability — KALLYAS CWE-862 | 5.3 | Medium | 2025-11-06 |
| CVE-2025-62016 | WordPress Kallyas theme <= 4.22.0 - Arbitrary File Upload vulnerability — KALLYAS CWE-434 | 9.9 | Critical | 2025-11-06 |
| CVE-2025-62017 | WordPress Kallyas theme <= 4.22.0 - Broken Access Control vulnerability — KALLYAS CWE-862 | 5.4 | Medium | 2025-11-06 |
This page lists every published CVE security advisory associated with hogash. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.